ShinyHunters hijacks Clop leak site via Grav flaw
ShinyHunters defaced Clop’s Tor leak site via a Grav CMS bug; Clop says only site content was exposed.
Extortion group ShinyHunters defaced the dark-web leak site of rival ransomware gang Clop (also called Cl0p) and demanded payment, with The Register describing an eight-figure ransom and Malwarebytes also reporting a demand for a public apology. Early reports said the attackers used a claimed unauthenticated file-upload bug in Grav CMS and took the onion-service keys; BleepingComputer later reported that Grav confirmed CVE-2026-42608, an unauthenticated path traversal in Grav core affecting Clop’s Grav 1.7.43 site, already fixed in Grav 2.0 and backported in 1.7.53.4. ShinyHunters claims stolen private keys, logs, source code, plugins, and records that could show which companies paid Clop, including during the Oracle E-Business Suite campaign linked to CVE-2025-61882, while Clop said the server held only site content, denied talks, and moved its Tor site. Infosecurity Magazine and The Register date the feud to 2025 rivalry over that Oracle zero-day; Malwarebytes instead said it started after ShinyHunters disrupted a Clop theft campaign. Coverage treats this as criminals targeting each other’s extortion infrastructure rather than a newly confirmed attack on an outside victim, and Dark Reading notes that a second-extortion risk for prior payers remains unconfirmed.
- On 21 September 2026 outlets reported ShinyHunters defaced rival ransomware gang Clop’s (also Cl0p) Tor leak site and demanded a ransom; The Register called the demand eight-figure, and Malwarebytes also cited a public apology.
- BleepingComputer (25 September) said Grav confirmed CVE-2026-42608, an unauthenticated path traversal in Grav core, on Clop’s Grav 1.7.43 install; it was fixed in Grav 2.0 and backported as 1.7.53.4. Malwarebytes had described a claimed…
- ShinyHunters claims onion-service private keys plus server or authentication logs, source code, and Grav plugins; Clop said the unpatched server held only site content, denied negotiations, and moved the leak site.
- Infosecurity Magazine and The Register trace the feud to 2025 use of Oracle E-Business Suite zero-day CVE-2025-61882; Malwarebytes said it began after ShinyHunters disrupted a Clop data-theft campaign.
- ShinyHunters threatens to expose companies that paid Clop and related Bitcoin addresses, including in the Oracle EBS campaign; Dark Reading said no victim organizations were named and the stolen dataset was not confirmed.
- SOCRadar framed the incident as a gang-on-gang takeover of extortion infrastructure, not a new ransomware attack on an outside organization.
- Malwarebytes: ShinyHunters has been active since 2019 and previously claimed 3.65 TB on about 9,000 academic institutions from Instructure; Clop’s PTC Windchill campaign named over 40 victims, including Shell and Philips.
Coverage timelineoldest first · each row is one article
- · 6d agoShinyHunters hacks rival extortion gang and takes over its dark web site
Malwarebytes Labs· 55
ShinyHunters claims it hacked rival extortion gang Clop's leak site via a Grav CMS flaw and seized its onion domain.
- · 5d agoShinyHunters Claim Hack of Rival Ransomware Gang Clop
Infosecurity Magazine· 70
ShinyHunters hacked rival ransomware gang Clop, defacing its leak site and claiming to have stolen operational data and private keys.
- · 5d agoClop gets a taste of its own medicine after ShinyHunters hijack leak site
The Register · Security· 72
Vulnerabilities in this storyAll →
- CVE-2025-618829.8100%Unauthenticated Takeover of Oracle E-Business Suite Concurrent Processingpublished · Oracle E-Business Suite (Oracle Concurrent Processing, BI Publisher Integration component) KEV ransomware